Suspicious
Suspect

2dc6f09c9bec451282cc82aa8a7131c0

Rar Archive
MD5: 2dc6f09c9bec451282cc82aa8a7131c0
Size: 765.62 KB
application/vnd.rar

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2dc6f09c9bec451282cc82aa8a7131c0
Sha1 93cd7889f250e24e3bb6c8306668b56ba50ef27f
Sha256 1ab6defd87d3efe97644b144b265cb9d1954f77a09586e70ed6b8a0d119fc8ed
Sha384 a773f1c95b61a36d9529d625fa231e14c64dbb804fac9357182bab1a0ca4ee9609435130d8c77f63153b6c8968ec733c
Sha512 a36ff33d3464dd5a090bdab1a50d7f43e487e3c0e02b8939f9a7bc30405e84c7624a0bbf8986071226fb0789e58397cf82214f5cf2d43b48ac3f9d0473a0a7be
SSDeep 12288:lLTX4+i5uTuFuSBP0RuD2Vz+aJHjcmvetD3GMNc3lWdKnpkO33ydcBfNS3zczXdD:RTxUuaPmRuD2IaBw4ep5c1LpkDiBfQzg
TLSH 3AF433388E1FE13B7E09BD2D616A6C0B4DAA819277D52C51E5A0FC2D3D3FB305B50686
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FleetManager.GlobalDashboardForm.resources
$this.Icon
[NBF]root.IconData
RI
[NBF]root.Data
FleetManager.ContractBiddingForm.resources
FleetManager.Properties.Resources.resources
xSAA
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FleetManager.GlobalDashboardForm.resources
$this.Icon
[NBF]root.IconData
RI
[NBF]root.Data
FleetManager.ContractBiddingForm.resources
FleetManager.Properties.Resources.resources
xSAA
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙